惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
SecWiki News
SecWiki News
博客园_首页
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
P
Palo Alto Networks Blog
V
Vulnerabilities – Threatpost
Project Zero
Project Zero
WordPress大学
WordPress大学
NISL@THU
NISL@THU
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Privacy & Cybersecurity Law Blog
Jina AI
Jina AI
AWS News Blog
AWS News Blog
Scott Helme
Scott Helme
Martin Fowler
Martin Fowler
C
Cybersecurity and Infrastructure Security Agency CISA
Forbes - Security
Forbes - Security
H
Heimdal Security Blog
小众软件
小众软件
I
Intezer
A
Arctic Wolf
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
O
OpenAI News
S
Security Affairs
阮一峰的网络日志
阮一峰的网络日志
Latest news
Latest news
G
GRAHAM CLULEY
Blog — PlanetScale
Blog — PlanetScale
J
Java Code Geeks
N
News and Events Feed by Topic
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
V2EX - 技术
V2EX - 技术
Stack Overflow Blog
Stack Overflow Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
L
LINUX DO - 最新话题
博客园 - Franky
P
Proofpoint News Feed
aimingoo的专栏
aimingoo的专栏
博客园 - 司徒正美
P
Proofpoint News Feed
S
Secure Thoughts
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
T
The Exploit Database - CXSecurity.com
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
F
Full Disclosure
Security Latest
Security Latest

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
Lattice-Based PQC "Limitations" Paper — A Reality Check
Marin Ivezic · 2026-05-10 · via PostQuantum – Quantum Computing, Quantum Security, PQC

May 10, 2026 – A preprint posted to arXiv on May 6, 2026, titled “Fundamental Limitations of Post-Quantum Cryptographic Architectures,” has been making the rounds in my security circles. The paper, authored by Jiho Jung, Donghwa Ji, Mingyu Lee, and Kabgyun Jeong at Seoul National University, argues that calling lattice-based cryptography “post-quantum” is premature because its security rests on unproven computational assumptions rather than proven theoretical lower bounds.

The paper has prompted a reaction I’ve been hearing from multiple contacts: “If PQC isn’t actually quantum-safe, maybe we should wait for something better before migrating.”

That conclusion is exactly wrong. And it reveals a misunderstanding of what this paper actually says, what cryptographers have always known about PQC, and why the case for migrating now is stronger than ever.

What the Paper Claims

The authors examine the Learning with Errors (LWE) problem, the mathematical foundation underlying NIST’s primary post-quantum standards: ML-KEM (FIPS 203, formerly CRYSTALS-Kyber), ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium), and the forthcoming FN-DSA (FIPS 206). They argue across four domains that LWE’s security is not absolute:

Complexity theory. There is no mathematical proof that LWE problems lie outside BQP (the class of problems efficiently solvable by quantum computers). The security assumption could, in principle, be wrong.

Information theory. Using Shannon’s noisy-channel coding theorem and Fano’s inequality, the authors argue that the noise injected into LWE ciphertexts does not permanently destroy the secret. The information is obscured, not erased.

Quantum error correction. The paper draws a structural analogy between LWE noise and the displacement errors corrected by Gottesman-Kitaev-Preskill (GKP) codes, arguing that quantum error correction techniques could theoretically “filter out” cryptographic noise.

Quantum learning theory. The GKZ algorithm (Grilo, Kerenidis, and Zijlstra, 2019) can solve LWE in polynomial time given access to quantum superposition samples of the LWE problem.

The paper’s conclusion: LWE-based cryptography is a “robust transitional alternative” but should not be considered unconditionally secure. The security stems from “transient physical bottlenecks rather than impenetrable theoretical boundaries.”

My Analysis

I want to be precise about what I think this paper gets right, what it gets wrong, and why the circulating “wait on PQC” interpretation is dangerous.

What the Paper Gets Right

The core observation is correct: lattice-based cryptography relies on computational hardness assumptions, not information-theoretic proofs of security. Nobody has proven that LWE is hard for quantum computers. The security of ML-KEM, ML-DSA, and every other lattice-based scheme rests on the assumption that no efficient quantum algorithm exists for these problems.

This is true. It has also been true since Oded Regev introduced LWE in 2005. Every lattice cryptographer knows this. NIST knows this. The NIST standardization documentation says this explicitly. The European ECCG’s Agreed Cryptographic Mechanisms v2.0 mandates hybrid deployment of lattice-based schemes with classical algorithms precisely because of this uncertainty. France’s ANSSI and Germany’s BSI have been saying this for years.

The paper is demolishing a position that no serious cryptographer holds. Nobody in the PQC community claims lattice-based cryptography offers “unconditional security” or that it is “fundamentally immune to quantum mechanics.” The term “post-quantum” means resistant to known quantum attacks, not provably immune to all possible quantum computation. This is a distinction the paper’s own text acknowledges but that its framing obscures.

What the Paper Gets Wrong

The paper’s arguments, while individually valid at a high theoretical level, contain significant gaps and overstatements when examined closely.

The GKZ algorithm requires quantum samples that nobody can prepare. The authors acknowledge that the GKZ algorithm, the most concrete quantum attack discussed, requires the adversary to prepare coherent quantum superpositions of LWE samples (quantum random access memory, or QRAM). They correctly identify this as a “profound physical bottleneck.” But the paper then suggests this bottleneck is being systematically dismantled by divide-and-conquer strategies and ε-QRAM optimizations, without providing evidence that these approaches work at cryptographically relevant parameter scales. The QRAM problem is one of the hardest open problems in quantum computing. Waving at theoretical optimizations is not the same as demonstrating a viable attack path.

The GKP error correction analogy is a structural observation, not an attack. The most creative section of the paper argues that LWE noise is “structurally equivalent” to the displacement errors corrected by GKP bosonic codes. This is an interesting physics observation, but it does not constitute a cryptographic attack. The paper provides no resource estimates, no analysis of what GKP-based “decryption” would require for standardized parameter sets (ML-KEM-768, ML-KEM-1024), and no engagement with the practical reality that GKP codes themselves are still in early experimental stages. Structural analogy is not operational equivalence.

The NISQ/hybrid claims are speculative. The paper cites variational quantum algorithms for LWE on noisy intermediate-scale quantum (NISQ) devices (Zeng et al., 2025) as evidence that the threat is not confined to fault-tolerant quantum computing. These algorithms have been demonstrated only on toy-scale problems, orders of magnitude smaller than any standardized parameter set. Extrapolating from a proof-of-concept on a handful of qubits to a threat against ML-KEM is like extrapolating from factoring the number 15 on a quantum computer to breaking RSA-2048. The gap is astronomical.

The paper does not engage with Module-LWE. NIST’s standardized algorithms use Module-LWE, not plain LWE. This structured variant introduces additional algebraic structure that affects both efficiency and security analysis. A paper claiming to assess the “fundamental limitations” of PQC architectures should engage with the specific mathematical problems underlying the actual deployed standards, not just the generic LWE problem.

What the Paper Does Not Say

Because the misreadings are already circulating, let me state explicitly what this paper does not claim:

It does not present a new quantum attack on LWE. The GKZ algorithm is from 2019. The information-theoretic arguments are textbook results (Shannon, 1948; Fano, 1949) applied to a cryptographic context. There is no novel result in this paper.

It does not claim that current PQC standards are broken or breakable with near-term quantum hardware. The authors explicitly call lattice-based cryptography a “robust transitional alternative.”

It does not provide any timeline for when the theoretical vulnerabilities it identifies could become practical. There are no resource estimates, no hardware projections, no connection to the CRQC Quantum Capability Framework or any equivalent analytical structure.

It does not address hash-based signature schemes (SLH-DSA), code-based encryption (HQC), or any non-lattice PQC approach. The title says “post-quantum cryptographic architectures” (plural), but the analysis covers only lattice-based schemes.

The “Wait for Something Better” Fallacy

Here is why the “maybe we should wait” reaction is not just wrong but actively harmful.

The entire PQC standardization process was designed for a world where hardness assumptions might turn out to be wrong. This is why NIST standardized multiple algorithmic families, not just lattice-based schemes. SLH-DSA’s security rests on hash functions, not lattice problems. HQC, the code-based backup now progressing through NIST’s process, relies on entirely different mathematical foundations. The system was built with algorithmic diversity and crypto-agility as explicit design goals.

If lattice-based assumptions were broken tomorrow (an event this paper does not come close to predicting), organizations with crypto-agile architectures could transition to hash-based and code-based alternatives. Organizations that “waited for something better” would still be running RSA and ECC, fully exposed to both the classical threat from a CRQC and the ongoing Harvest Now, Decrypt Later threat.

The irony is striking: a paper about the theoretical fragility of one cryptographic assumption is being used to justify continued reliance on cryptographic assumptions (RSA, ECC) that we know are broken by Shor’s algorithm. The “known bad” is being preferred over the “possibly imperfect” — which is not a rational security strategy by any definition.

The Real Lesson

If anything, this paper reinforces what I have been arguing for years: treat PQC migration as an ongoing discipline, not a one-time switch. Build crypto-agility into your architecture so you can swap algorithms when the cryptanalytic landscape evolves. Deploy hybrid implementations as the European ECCG recommends. Maintain awareness of the research frontier. And above all, start now, because the deadlines are already set — by regulators, by insurers, by supply chain partners, by procurement requirements — regardless of whether any particular hardness assumption holds.

The Jung et al. paper is a competent survey of known theoretical observations about lattice-based cryptography, repackaged with a provocative title. It will be cited by quantum-panic vendors selling alternative solutions and by procrastination enthusiasts looking for reasons to delay. It deserves neither role.

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum